Water and wastewater utilities in at least seven states have now reported cybersecurity incidents involving Internet-facing programmable logic controllers (PLCs), according to the FBI and the Environmental Protection Agency (EPA).
All the incidents have taken place since July 27, and they have seen malicious actors remotely access Internet-facing PLCs including Rockwell Automation/Allen-Bradley models, changing device IP addresses and passwords. The activity resulted in temporary loss of monitoring or control functions at some facilities, the agencies said via a public service announcement. This announcement focuses on the Rockwell devices, but it advises operators using other brands to take precautions, too. Specific states were not named.
The announcement also said incidents have resulted in operational impacts such as pressure loss and flooding, warning that pressure loss specifically could allow untreated groundwater to seep into pipes. The extent of the impact depends on PLC configuration and whether utilities can shift affected systems to manual operation.
The FBI and EPA also revealed details about the methods of the attacks. Malicious actors gain remote access to Internet-facing PLCs and then change the IP addresses and passwords, locking the utilities out of monitoring and control functions. Attackers may also alter programming that instructs pumps, valves and other equipment on how to operate.
Meanwhile, Minnesota officials announced this week that at least 30 community water systems across the state were hit with malicious cyber activity, and an investigation is ongoing there. The Minnesota IT Services (MNIT) announcement said that although there are similarities among attacks, there has not been an attribution nor have investigators determined the attacks involved the same actor. The announcement didn’t specifically name manufacturers of the compromised devices or the utilities.
While the activity described by MNIT is consistent with the FBI’s description of malicious activity, officials emphasized that impacted systems do not equate to water service disruptions. Neither state health officials nor targeted systems have reported any public health risks from the attacks, which happened July 26 and 27, according to an earlier statement.
Four Minnesota city water organizations publicly announced cyber incidents, but others are unidentified. Braham’s water plant went temporarily offline; Plymouth announced impacts to automated controls and cellular-connected equipment at water towers and lift stations; South St. Paul announced a cybersecurity incident on automated controls; and Maple Plain declared a temporary emergency.
MNIT’s recommendations closely align with guidance from the FBI and EPA, urging water and wastewater systems to identify and secure Internet-accessible operational technology, including PLCs and human-machine interfaces. Recommended steps include removing unnecessary Internet access, strengthening access and passwords, requiring multifactor authentication, reviewing logs and configurations, separating OT from networks, keeping accurate inventories, maintaining offline backups, and testing incident-response and recovery planning.
The incidents come as the Cybersecurity and Infrastructure Security Agency and its federal partners continue to warn that Internet-connected industrial control systems remain attractive targets for malicious actors. In an advisory updated July 22 and redistributed on July 30, the agency said Iranian-affiliated attackers have exploited programmable logic controllers across multiple U.S. critical infrastructure sectors.
Minnesota officials, however, haven’t attributed the incidents affecting the state’s water systems to a specific threat actor. Federal agencies also continue to recommend that utilities remove PLCs from direct Internet exposure, restrict remote access and regularly verify that controller programming has not been altered.
